NextPass

Legal

Who runs this site, the rules for using it and its API, and exactly what data passes through it - which is very little.

Draft. These texts have not been reviewed yet, and the fields marked to be completed must be filled before any commercial use.

Legal notice

Mentions légales - LCEN, article 6
Publisher
to be completed
Legal form
to be completed
SIREN
to be completed
VAT number
to be completed
Address
to be completed
Contact
to be completed
Publication director
to be completed

Hosting

The website is served by Vercel Inc. The prediction API runs on Render Services, Inc. Both are established in the United States. Their postal addresses and telephone numbers are published on those pages. to be completed: copy them here

Intellectual property

The source code is published on GitHub under the terms stated there. Orbital elements come from CelesTrak; coastlines from Natural Earth, in the public domain.

Terms of use

The service

NextPass computes when satellites pass over a place on Earth, from public orbital elements and the SGP4 model. The website is free to use. The API is available with a key, under the quotas of the chosen plan.

Predictions are estimates

Times and positions come from a model fed with elements published hours or days earlier, and their accuracy degrades with that age - the methodology gives the orders of magnitude. They are suitable for observation, photography, amateur radio and planning. They must not be used for any purpose where an error could endanger people or property, such as collision avoidance, navigation or safety of flight.

Fair use

  • The website shares one anonymous budget of 200 predictions a day among all visitors. Automated use of it is not permitted; integrations use the API with their own key.
  • An API key is personal to its account. Keep it secret, keep it on a server, and do not share or resell access.
  • Do not try to bypass quotas, rate limits or authentication, or to disrupt the service.

A key used against these rules may be revoked.

Paid plans

Paid plans are not on sale yet. When they open, payment will be handled by Stripe; prices and taxes will be shown before confirmation, subscriptions will renew monthly and can be cancelled at any time from the account page, with access kept until the end of the paid period. Quotas reset at 00:00 UTC on the first of each month.

Availability and liability

The service is provided as is, without a guaranteed level of availability. The live state is on the status page. To the extent permitted by law, the operator is not liable for indirect losses resulting from the use of the predictions or from an interruption of the service.

Changes and applicable law

These terms may change; the date of the current version is shown below. They are governed by French law. to be completed: version date, competent court

Privacy

GDPR

Using the predictor

  • No account needed. The predictor itself sets no cookie and stores nothing in your browser; only the advertising below may, and in Europe only with your consent.
  • The coordinates you enter are sent to the prediction API to compute the passes, and appear in the page address so a result can be shared. They are not written to any database; an identical query may be answered from memory for up to five minutes.
  • "Use my position" asks your browser, only when you press it. The position is rounded to about ten metres and used only to fill the form.
  • Fonts are served by this site, not by a third party, so loading the page does not send your address to a font provider.
  • Audience measurement uses Vercel Web Analytics, which counts page views without cookies and without identifying visitors.
  • Advertising is served by Google AdSense, which chooses where ads appear and receives your IP address to deliver them. In the European Economic Area, the United Kingdom and Switzerland, Google asks for your consent before using cookies or personal data for ads, and you can change that choice at any time. Google explains how it uses data from the sites that show its ads.

API accounts

  • Sign-in is through GitHub. The account keeps your GitHub numeric identifier - not your name, email address or repositories.
  • API keys are stored only as a SHA-256 hash: nobody, including the operator, can read a key back.
  • Usage counters record how many requests each key made per UTC day, to enforce quotas.
  • Payments, when open, are handled by Stripe. The account keeps a Stripe customer identifier; card details never reach this service.
  • Cookies on the account page are limited to the sign-in session and its CSRF protection, which the page cannot work without.

Hosting logs

Like any website, the hosting providers receive technical data with each request - notably the IP address - to deliver pages and protect against abuse. to be completed: retention period of these logs

Legal basis, recipients and transfers

Account data is processed to provide the service you asked for (performance of a contract); logs and audience measurement under the operator's legitimate interest in running a secure, working service; advertising cookies and personalised ads only with your consent. Data is processed by Vercel, Render, GitHub, Google for advertising and, for payments, Stripe - companies established in the United States, which may involve transfers outside the European Union. to be completed: transfer safeguards, database host

Retention

Account data is kept while the account exists. to be completed: retention after closure, and of usage counters and invoices

Your rights

You can access, correct, delete or export your data, object to its processing, or restrict it. You can revoke your API key yourself from the account page. To close an account or exercise any other right, write toto be completed: contact address. You can also lodge a complaint with the CNIL.